Skip to content

Account security

This page is about your own login: the email address and password you sign in with, and the optional two-factor authentication that protects it. It applies to the web dashboard and the merchant app, which share one account.

A staff PIN at a shared till is a different thing entirely, covered on Team and staff. This page is your personal account.

Sign in with your email address and password on the web at Sign in, or in the merchant app. Tick Remember me to stay signed in on that device for 30 days; leave it off and the session lasts 24 hours. However often you use it, a sign-in never lasts longer than 30 days: after that you are asked to sign in again, in the web dashboard and the merchant app alike.

For your security, a failed sign-in always says the same thing, “Invalid email or password”, whether it was the email or the password that was wrong. It never tells an outsider which part they got right.

You have to confirm your email address before you can sign in for the first time (see Confirming your email).

No account yet? Choose Create an account on the Sign in page (see Getting started). If you started from Sign in with Musqet in another app, you return to it once you have confirmed your email and signed in.

Sign out from the account menu on whichever device you are using. Signing out is per device: it ends your session on that device only. Changing or resetting your password is the exception: it signs you out everywhere else too.

A paired terminal signs in on its own and stays signed in so it can keep taking payments. Signing out of the dashboard or the app does not sign a terminal out; sign out on the terminal itself when you need to. If you think your account has been used by someone else, see If your account may be compromised.

On the web Sign in page, choose Forgot password and enter your email address. If we have an account for it, we email you a reset link. For your security we always say the same thing whether or not the address is registered, so the reply never confirms who has an account.

The link is good for 15 minutes and works once. If it has lapsed or was already used, the page says so and offers Request a new link. Otherwise open it and set a new password (it is checked for strength and against known-breached passwords), then sign in with it. Resetting also clears any lockout and signs your account out on every device, including the merchant app, so sign back in with the new password.

Password reset is done on the web. If you use the merchant app, open the web dashboard to reset, then sign back in on the app.

While signed in, change your password on the Settings page. You enter your current password to confirm it is you, then your new one. This is available on the web.

Changing your password signs your account out on every other device, including the merchant app. The browser you changed it in stays signed in. A paired terminal has its own sign-in and is not affected.

New accounts confirm their email address from a link we send. The link opens a page with a Confirm my email button: only pressing it confirms, so a mail filter that opens links cannot do it for you. The link is good for 24 hours. If it has lapsed, opening it asks for your email address: enter it and choose Send a new link. If the email never arrives, check your junk or spam folder. This is the same confirmation described in Getting started.

Someone invited to a business’s team confirms their email by finishing their account from the invitation instead, as described in Team and staff.

Two-factor authentication adds a second step after your password. That step can be an authenticator app (such as Google Authenticator or 1Password), a passkey, or both. You set it up from the Settings page on the web, and the page then says Two-factor authentication is on.

To use an authenticator app, choose Set up authenticator app, scan the QR code once, and enter the six-digit code to confirm. If you already use passkeys, you confirm it is you first.

Once it is on, signing in asks for the second step after your password, and it is used to confirm sensitive changes to your account (see Confirming it is you). It is set up and managed on the web.

Choose Remove authenticator app on Settings and confirm it is you. If you have passkeys, they keep two-factor authentication on, along with your backup codes. If the app is your only second step, removing it turns two-factor authentication off and your backup codes stop working.

When you turn on two-factor authentication you are given a set of backup codes, whether you start with an authenticator app or a passkey. Save them somewhere safe and private: they are shown once and we only keep a scrambled copy, so we cannot read them back to you. You can regenerate a fresh set from Settings at any time, which retires the old ones. Setting up an authenticator app also gives you a fresh set, which replaces the old ones.

If you lose your authenticator app and your passkeys, contact support and we will help you back in.

A passkey lets you complete the second step with your device’s screen lock, a security key or your phone, instead of typing a six-digit code. You can use passkeys on their own, with no authenticator app, or alongside one.

To add a passkey, open Settings on the web (or Profile in the partner portal) and choose Add a passkey in the Passkeys section. Give it a name if you like, then confirm it is you:

  • If two-factor authentication is not on yet, enter your password. Your first passkey turns two-factor authentication on, and once it is created you are shown your backup codes to save.
  • If it is already on, enter your password and a code from your authenticator app, or choose Use a passkey instead. With no authenticator app, your browser asks for one of your passkeys.

Then choose Create passkey and follow your browser’s steps. The passkey then appears in the list, with when it was added and when it was last used. You can add up to 10.

When you sign in on the web and are asked for your code, choose Use a passkey and follow your browser’s steps to finish signing in. If your account has no authenticator app, you are asked for a passkey straight away. This works on the merchant dashboard and the partner portal. The option only appears once your account has a passkey, and in a browser that supports them.

The merchant app does not use passkeys. It asks for the code from your authenticator app. If your account has passkeys but no authenticator app, the app says so and links you to Settings on the web to add one; a backup code still gets you in, but keep those for emergencies. If you use the merchant app and your only second step is passkeys, Settings on the web reminds you to set up an authenticator app as well.

You can rename a passkey at any time. Removing one asks you to confirm it is you, and it can no longer be used to sign in. If it is your only second step, removing it turns two-factor authentication off and your backup codes stop working.

Some especially sensitive changes ask you to confirm it is you with your password and your second step, even though you are already signed in. This currently applies to:

  • changing the bitcoin address your business receives to,
  • changing the bitcoin address on your personal wallet,
  • adding or removing your authenticator app or a passkey, and
  • regenerating your backup codes.

On the web, the second step is a code from your authenticator app, or a passkey if you have one: choose Use a passkey instead, or, with no authenticator app, your browser asks for a passkey after your password.

You need two-factor authentication switched on to make these changes. If it is not on, you are told so instead of being shown the confirmation form: the merchant app explains what is needed and offers a link to your Settings page on the web. Turn two-factor authentication on there, return to the app, and the change is available. The merchant app confirms with a code from your authenticator app. If your account uses passkeys only, the app asks you to add an authenticator app on the web instead, with the same link to Settings, or you can make the change on the web.

After five wrong passwords in a row, your account is locked for 15 minutes. We email you when this happens. The lock clears on its own after 15 minutes, and immediately if you sign in correctly or reset your password. There is nothing else you need to do but wait or reset.

This is a different message from being locked out, and it means something different. We also limit how many sign-in attempts we will accept in a short period, both for one email address and from one internet connection. If you see “Too many requests. Please try again later.”, you have run into that limit rather than the lockout above.

It clears on its own within 15 minutes. You will not get an email about it, because it is not a lock on your account and there is nothing on the account to clear.

If several people work from the same premises and share one internet connection, they each get their own allowance, so one colleague repeatedly mistyping their password will not stop the rest of you signing in.

Your Settings page shows a sign-in history: recent sign-ins and sign-in attempts on your account, each with when it happened and its result. Use it to spot anything you do not recognise. If something looks wrong, change your password and see If your account may be compromised.

Your Settings page is where you look after the security of your account: your password, two-factor authentication and your sign-in history. Open it from Settings inside a business, or choose Profile and security from the account menu, which works even when you have no business to open. Your name was set when you signed up. Your email address is not something you can change yourself; contact support if it needs to change.

You can view Musqet in more than one language.

  • The merchant app offers English, Spanish, French, German and Portuguese, from the sign-in screen and from the menu.
  • The web dashboard supports four of these: English, Spanish, French and German. The in-dashboard language switch is still being rolled out, so you may not see it yet.
  • A terminal offers English, German and Spanish. You can set a terminal’s display language on the terminal itself, from its Settings screen, or from the terminal’s settings in the dashboard.

If you think someone else has your password, change it straight away. That signs your account out on every other device, so a stolen session of yours cannot keep being used. Then check your sign-in history for anything unfamiliar, and contact support if something looks wrong.

A paired terminal is a separate device with its own sign-in, and signing your account out does not end its session. If a terminal itself may be affected, remove or disconnect it from your devices settings (or ask support to), which ends the terminal’s session too.

What you seeWhat it meansWhat to do
”Invalid email or password”The email or the password was wrong (we do not say which)Try again carefully; use Forgot password if unsure
You are locked out after several triesFive wrong passwords locks the account for 15 minutesWait 15 minutes, or reset your password to clear it at once
”Too many requests. Please try again later.”You have hit the limit on sign-in attempts in a short period. This is not the same as being locked out, and you will not be emailed about itWait up to 15 minutes and try again. If you are unsure of your password, use Forgot password rather than guessing
The reset link does not workReset links expire after 15 minutes and work onceRequest a fresh link from Forgot password
No reset option in the appPassword reset is on the webOpen the web dashboard, reset there, then sign back in on the app
The confirmation email never arrivedIt went to spam, or the address was mistypedResend from Verify email and check your spam folder
You lost your authenticator appYour second step was on that appSign in with a passkey or a backup code. With a passkey you can then remove the old app from Settings; otherwise contact support
You were signed out of the app after changing your passwordChanging or resetting your password signs your account out on every other deviceSign back in with the new password
A terminal is still signed in after you signed outSigning out is per device; a terminal keeps its own sessionSign out on the terminal itself, or remove the device from your devices settings to end its session
You cannot change your email addressEmail is not self-serviceContact support to change it
There is no Use a passkey option when you sign inYour account has no passkey yet, or the browser does not support passkeysEnter the code from your authenticator app, or add a passkey from Settings
”The passkey request was cancelled or timed out.”The browser’s passkey prompt was closed or took too longChoose Use a passkey again, or enter your code
You cannot add a passkeyThe browser does not support passkeys, or you already have 10Try another browser, or remove a passkey you no longer use
  • Getting started for creating your account and confirming your email
  • Team and staff for staff PINs and the till roster, which are separate from your login